| Case | Discloser | Target pipeline | Injection channel | Impact | Date |
|---|---|---|---|---|---|
| EchoLeak (CVE-2025-32711) | Aim Security | M365 Copilot (email RAG) | Poisoned inbound email (markdown auto-fetch image) | Zero-click exfil of internal mail/files; CVSS 9.3 | 2025-06 |
| ForcedLeak (CVSS 9.4) | Noma Security | Salesforce Agentforce/Einstein (CRM) | Poisoned Web-to-Lead form field | Indirect injection → CRM data exfil to whitelisted domain | 2025-09 |
| AgentFlayer (Black Hat) | Zenity (Bargury) | ChatGPT Connectors, Copilot Studio, Cursor+Jira, Einstein, Gemini | Poisoned document (white-on-white) shared into Drive/connector | Zero-click exfil of connected cloud data via image-URL params | 2025-08 |
|